drogue-cloud-core Helm chart
drogue-iotVerified publisherScored 14 Sept 2026
Drogue IoT Cloud core installation
Latest 0.7.11 3 years agoapp version 0.11.0 0Artifact Hub
drogue-cloud-core 0.7.11 deploys 22 container images: bitnami/postgresql, ghcr.io/drogue-iot/mqtt-integration, ghcr.io/drogue-iot/websocket-integration, swaggerapi/swagger-ui and 18 more. Across the 21 measured, 2,823 findings — 141 critical, 193 high — 63 on CISA KEV. The highest contribution is ALPINE-CVE-2023-38545 in curl 7.80.0-r1, fixed in 8.4.0-r0. Chart.yaml declares kubeVersion >= 1.22.0-0; rendered for Kubernetes 1.22.0.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | ALPINE-CVE-2023-38545 | curl | 8.4.0-r0 |
| Critical | ALPINE-CVE-2023-4863KEV | libwebp | 1.2.2-r2 |
| Critical | RHSA-2024:2722 | glibc | 0:2.28-236.el8_9.13 |
| Critical | RHSA-2024:3339 | glibc | 0:2.34-100.el9_4.2 |
| Critical | GHSA-mjmj-j48q-9wg2 | snakeyaml | 2.0 |
| Critical | RHSA-2025:1738 | libpq | 0:13.20-1.el9_5 |
| Critical | RHSA-2023:5453KEV | glibc | 0:2.34-60.el9_2.7 |
| Critical | RHSA-2023:5455KEV | glibc | 0:2.28-225.el8_8.6 |
| Critical | RHSA-2026:1473 | openssl | 1:3.5.1-7.el9_7 |
| Critical | ALPINE-CVE-2023-44487KEV | nghttp2 | 1.46.0-r2 |
| Critical | RHEA-2023:6562KEV | nginx | 1:1.22.1-5.module+el9.3.0.z+20438+032561a0 |
| Critical | RHSA-2023:5838KEV | nghttp2 | 0:1.43.0-5.el9_2.1 |
| Critical | RHSA-2023:5763 | curl | 0:7.76.1-23.el9_2.4 |
| Critical | RHSA-2023:6745 | curl | 0:7.76.1-26.el9_3.2 |
| Critical | RHSA-2026:18029 | nginx | 2:1.20.1-24.el9_7.3 |
| Critical | RHSA-2025:11992 | sqlite | 0:3.34.1-8.el9_6 |
| High | RHSA-2025:0083 | cups | 1:2.2.6-62.el8_10 |
| High | RHSA-2023:0946 | openssl | 1:3.0.1-47.el9_1 |
| High | RHSA-2023:1405 | openssl | 1:1.1.1k-9.el8_7 |
| High | ALPINE-CVE-2023-0286 | openssl | 1.1.1t-r0 |
| High | RHSA-2025:1346KEV | gcc | 0:11.5.0-5.el9_5 |
| High | ALPINE-CVE-2022-32214 | nodejs | 16.17.1-r0 |
| High | ALPINE-CVE-2023-2650 | openssl | 1.1.1u-r0 |
| High | RHSA-2023:3722 | openssl | 1:3.0.7-16.el9_2 |
| High | RHSA-2025:9318 | javapackages-tools | 0:5.3.0-2.module+el8.10.0+23274+27840b45 |
| High | RHSA-2024:0628 | libssh | 0:0.9.6-13.el8_9 |
| High | ALPINE-CVE-2022-32215 | nodejs | 16.17.1-r0 |
| High | ALPINE-CVE-2022-37434 | zlib | 1.2.12-r2 |
| High | RHSA-2024:5529 | curl | 0:7.76.1-29.el9_4.1 |
| High | RHSA-2026:6923 | nginx | 1:1.24.0-5.module+el9.7.0+24151+c43a3acf.2 |
| High | RHSA-2026:7002 | nginx | 2:1.20.1-24.el9_7.2 |
| High | RHSA-2026:7343 | nginx | 2:1.26.3-2.module+el9.7.0+24173+4204b761.1 |
| High | RHSA-2024:6783 | openssl | 1:3.0.7-28.el9_4 |
| High | RHSA-2024:3501 | nghttp2 | 0:1.43.0-5.el9_4.3 |
| High | ALPINE-CVE-2022-32213 | nodejs | 16.17.1-r0 |
| High | RHSA-2024:9333 | openssl | 1:3.2.2-6.el9_5 |
| High | RHSA-2024:9474 | krb5 | 0:1.21.1-4.el9_5 |
| High | RHSA-2023:0173 | libxml2 | 0:2.9.7-15.el8_7.1 |
| High | RHSA-2023:0338 | libxml2 | 0:2.9.13-3.el9_1 |
| High | ALPINE-CVE-2022-40303 | libxml2 | 2.9.14-r2 |
| High | ALPINE-CVE-2022-32206 | curl | 7.80.0-r2 |
| High | RHSA-2023:3591 | python3 | 0:3.6.8-51.el8_8.1 |
| High | ALPINE-CVE-2022-4450 | openssl | 1.1.1t-r0 |
| High | RHSA-2025:21776 | expat | 0:2.5.0-1.el8_10 |
| High | ALPINE-CVE-2022-43551 | curl | 7.80.0-r5 |
| High | ALPINE-CVE-2022-32207 | curl | 7.80.0-r2 |
| Medium | RHSA-2026:28212 | nginx | 1:1.24.0-7.module+el9.8.0+24379+0344c460.2 |
| Medium | RHSA-2023:2570 | krb5 | 0:1.20.1-8.el9 |
| Medium | RHSA-2025:11035 | lz4 | 0:1.8.3-5.el8_10 |
| Medium | GHSA-24rp-q3w6-vc56 | postgresql | 42.5.5 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 0.7.11latest | 3 years ago | 0.11.0 | 1411938501,639 | 55,666 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.